cbcvebase.

Freedesktop Dbus vulnerabilities

28 known vulnerabilities affecting freedesktop/dbus.

Total CVEs
28
CISA KEV
0
Public exploits
2
Exploited in wild
0
Severity breakdown
HIGH2MEDIUM11LOW15

Vulnerabilities

Page 2 of 2
CVE-2013-2168P4LOWCVSS 1.9v1.4.0v1.4.1+19 more2013-07-03
CVE-2013-2168 [LOW] CWE-20 CVE-2013-2168: The _dbus_printf_string_upper_bound function in dbus/dbus-sysdeps-unix.c in D-Bus (aka DBus) 1.4.x b The _dbus_printf_string_upper_bound function in dbus/dbus-sysdeps-unix.c in D-Bus (aka DBus) 1.4.x before 1.4.26, 1.6.x before 1.6.12, and 1.7.x before 1.7.4 allows local users to cause a denial of service (service crash) via a crafted message.
nvdosv
CVE-2014-3637P4LOWCVSS 2.1v1.3.0v1.3.1+37 more2014-09-22
CVE-2014-3637 [LOW] CWE-17 CVE-2014-3637: D-Bus 1.3.0 through 1.6.x before 1.6.24 and 1.8.x before 1.8.8 does not properly close connections f D-Bus 1.3.0 through 1.6.x before 1.6.24 and 1.8.x before 1.8.8 does not properly close connections for processes that have terminated, which allows local users to cause a denial of service via a D-bus message containing a D-Bus connection file descriptor.
nvdosv
CVE-2014-3639P4LOWCVSS 2.1v1.6.0v1.6.2+13 more2014-09-22
CVE-2014-3639 [LOW] CWE-399 CVE-2014-3639: The dbus-daemon in D-Bus before 1.6.24 and 1.8.x before 1.8.8 does not properly close old connection The dbus-daemon in D-Bus before 1.6.24 and 1.8.x before 1.8.8 does not properly close old connections, which allows local users to cause a denial of service (incomplete connection consumption and prevention of new connections) via a large number of incomplete connections.
nvdosv
CVE-2014-3638P4LOWCVSS 2.1v1.6.0v1.6.2+13 more2014-09-22
CVE-2014-3638 [LOW] CWE-399 CVE-2014-3638: The bus_connections_check_reply function in config-parser.c in D-Bus before 1.6.24 and 1.8.x before The bus_connections_check_reply function in config-parser.c in D-Bus before 1.6.24 and 1.8.x before 1.8.8 allows local users to cause a denial of service (CPU consumption) via a large number of method calls.
nvdosv
CVE-2014-3636P4LOWCVSS 1.9v1.8.0v1.8.2+2 more2014-10-25
CVE-2014-3636 [LOW] CWE-399 CVE-2014-3636: D-Bus 1.3.0 through 1.6.x before 1.6.24 and 1.8.x before 1.8.8 allows local users to (1) cause a den D-Bus 1.3.0 through 1.6.x before 1.6.24 and 1.8.x before 1.8.8 allows local users to (1) cause a denial of service (prevention of new connections and connection drop) by queuing the maximum number of file descriptors or (2) cause a denial of service (disconnect) via multiple messages that combine to have more than the allowed number of file descriptors f
nvdosv
CVE-2010-4352P4LOWCVSS 2.1≥ 0, < 1.2.24-42010-12-30
CVE-2010-4352 [LOW] CVE-2010-4352: Stack consumption vulnerability in D-Bus (aka DBus) before 1 Stack consumption vulnerability in D-Bus (aka DBus) before 1.4.1 allows local users to cause a denial of service (daemon crash) via a message containing many nested variants.
osv
CVE-2015-0245P4LOWCVSS 1.9v1.4.0v1.4.1+46 more2015-02-13
CVE-2015-0245 [LOW] CWE-362 CVE-2015-0245: D-Bus 1.4.x through 1.6.x before 1.6.30, 1.8.x before 1.8.16, and 1.9.x before 1.9.10 does not valid D-Bus 1.4.x through 1.6.x before 1.6.30, 1.8.x before 1.8.16, and 1.9.x before 1.9.10 does not validate the source of ActivationFailure signals, which allows local users to cause a denial of service (activation failure error returned) by leveraging a race condition involving sending an ActivationFailure signal before systemd responds.
nvdosv
CVE-2006-6107P4LOWCVSS 1.7≥ 0, < 1.0.2-12006-12-14
CVE-2006-6107 [LOW] CVE-2006-6107: Unspecified vulnerability in the match_rule_equal function in bus/signals Unspecified vulnerability in the match_rule_equal function in bus/signals.c in D-Bus before 1.0.2 allows local applications to remove match rules for other applications and cause a denial of service (lost process messages).
osv
Freedesktop Dbus vulnerabilities | cvebase